Back to Gitlabhq

Detected secrets

doc/user/application_security/secret_detection/detected_secrets.md

18.11.231.3 KB
Original Source

{{< details >}}

  • Tier: Free, Premium, Ultimate
  • Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated

{{< /details >}}

This table lists the secrets detected by:

  • Pipeline secret detection
  • Client-side secret detection
  • Secret push protection

Secret detection rules are updated in the default ruleset. Detected secrets with patterns that have been removed or updated remain open so you can triage them.

If you want to add a new secret detection rule, you can propose new detection rules for all GitLab users, or customize rulesets for your specific project.

<!-- markdownlint-disable MD044 --> <!-- vale gitlab_base.Spelling = NO --> <!-- vale gitlab_base.SentenceSpacing = NO -->
DescriptionIDPipeline secret detectionClient-side secret detectionSecret push protection
Adafruit IO KeyAdafruitIOKey{{< yes >}}{{< no >}}{{< yes >}}
Adobe Client ID (OAuth Web)Adobe Client ID (Oauth Web){{< yes >}}{{< no >}}{{< no >}}
Adobe client secretAdobe Client Secret{{< yes >}}{{< no >}}{{< yes >}}
Adobe IMS Access TokenAdobeIMSAccessToken{{< yes >}}{{< no >}}{{< no >}}
Age secret keyAge secret key{{< yes >}}{{< no >}}{{< no >}}
Aiven Service PasswordAivenServicePassword{{< yes >}}{{< no >}}{{< yes >}}
Alibaba AccessKey IDAlibaba AccessKey ID{{< yes >}}{{< no >}}{{< no >}}
Alibaba Secret KeyAlibaba Secret Key{{< yes >}}{{< no >}}{{< no >}}
Amazon OAuth Client IDAmazonOAuthClientID{{< yes >}}{{< no >}}{{< yes >}}
Anthropic API keyanthropic_key{{< yes >}}{{< yes >}}{{< yes >}}
Artifactory API KeyArtifactoryApiKey{{< yes >}}{{< no >}}{{< yes >}}
Artifactory Identity TokenArtifactoryIdentityToken{{< yes >}}{{< no >}}{{< yes >}}
Asana client IDAsana Client ID{{< yes >}}{{< no >}}{{< no >}}
Asana client secretAsana Client Secret{{< yes >}}{{< no >}}{{< no >}}
Asana Personal Access Token V1AsanaPersonalAccessTokenV1{{< yes >}}{{< no >}}{{< yes >}}
Asana Personal Access Token V2AsanaPersonalAccessTokenV2{{< yes >}}{{< no >}}{{< yes >}}
Atlassian API KeyAtlassianApiKey{{< yes >}}{{< no >}}{{< yes >}}
Atlassian API tokenAtlassian API token{{< yes >}}{{< no >}}{{< no >}}
Atlassian User API TokenAtlassianUserApiToken{{< yes >}}{{< no >}}{{< yes >}}
Auth0 Client SecretAuth0ClientSecret{{< yes >}}{{< no >}}{{< no >}}
AWS Access Key IDAWS{{< yes >}}{{< no >}}{{< yes >}}
AWS Access Secret KeyAWSSecretAccessKey{{< yes >}}{{< no >}}{{< no >}}
AWS Session TokenAWSSessionToken{{< yes >}}{{< no >}}{{< yes >}}
AWS Cognito Identity Pool IDAWSCognitoIdentityPoolID{{< yes >}}{{< no >}}{{< no >}}
AWS Bedrock KeyAWSBedrockKey{{< yes >}}{{< no >}}{{< no >}}
AWS Bedrock Short-lived KeyAWSBedrockShortLivedKey{{< yes >}}{{< no >}}{{< yes >}}
Azure API Management Gateway KeyAzureAPIManagementGatewayKey{{< yes >}}{{< no >}}{{< yes >}}
Azure API Management Direct KeyAzureAPIManagementDirectKey{{< yes >}}{{< no >}}{{< no >}}
Azure App ConfigAzureAppConfigConnectionString{{< yes >}}{{< no >}}{{< yes >}}
Azure Communication ServicesAzureCommServicesConnectionString{{< yes >}}{{< no >}}{{< yes >}}
Azure Cosmos DB CredentialsAzureCosmosDBCredentials{{< yes >}}{{< no >}}{{< no >}}
Azure Entra Client SecretAzureEntraClientSecret{{< yes >}}{{< no >}}{{< yes >}}
Azure Entra Client ID TokenAzureEntraIDToken{{< yes >}}{{< no >}}{{< yes >}}
Azure EventGrid Access KeyAzureEventGridAccessKey{{< yes >}}{{< no >}}{{< no >}}
Azure Functions API KeyAzureFunctionsAPIKey{{< yes >}}{{< no >}}{{< yes >}}
Azure Logic App SASAzureLogicAppSAS{{< yes >}}{{< no >}}{{< yes >}}
Azure OpenAI API KeyAzureOpenAIAPIKey{{< yes >}}{{< no >}}{{< no >}}
Azure Personal Access TokenAzurePersonalAccessToken{{< yes >}}{{< no >}}{{< no >}}
Azure SignalR Access KeyAzureSignalRAccessKey{{< yes >}}{{< no >}}{{< yes >}}
Beamer API tokenBeamer API token{{< yes >}}{{< no >}}{{< no >}}
Bitbucket client IDBitbucket client ID{{< yes >}}{{< no >}}{{< no >}}
Bitbucket client secretBitbucket client secret{{< yes >}}{{< no >}}{{< no >}}
Brevo API tokenSendinblue API token{{< yes >}}{{< no >}}{{< yes >}}
Brevo SMTP tokenSendinblue SMTP token{{< yes >}}{{< no >}}{{< yes >}}
Canada Digital Service Notify API KeyCDSCanadaNotifyAPIKey{{< yes >}}{{< no >}}{{< yes >}}
CircleCI access tokenCircleCI access tokens{{< yes >}}{{< no >}}{{< no >}}
CircleCI Personal Access TokenCircleCIPersonalAccessToken{{< yes >}}{{< no >}}{{< yes >}}
Clojars deploy tokenClojars API token{{< yes >}}{{< no >}}{{< no >}}
Contentful delivery API tokenContentful delivery API token{{< yes >}}{{< no >}}{{< no >}}
Contentful personal access tokenContentfulPersonalAccessToken{{< yes >}}{{< no >}}{{< yes >}}
Contentful preview API tokenContentful preview API token{{< yes >}}{{< no >}}{{< no >}}
Databricks API tokenDatabricks API token{{< yes >}}{{< no >}}{{< no >}}
DataDog API KeyDataDogAPIKey{{< yes >}}{{< no >}}{{< no >}}
DigitalOcean OAuth access tokendigitalocean-access-token{{< yes >}}{{< no >}}{{< no >}}
DigitalOcean personal access tokendigitalocean-pat{{< yes >}}{{< no >}}{{< no >}}
DigitalOcean refresh tokendigitalocean-refresh-token{{< yes >}}{{< no >}}{{< no >}}
Discord API keyDiscord API key{{< yes >}}{{< no >}}{{< no >}}
Discord client IDDiscord client ID{{< yes >}}{{< no >}}{{< no >}}
Discord client secretDiscord client secret{{< yes >}}{{< no >}}{{< no >}}
Docker Personal Access TokenDockerPersonalAccessToken{{< yes >}}{{< no >}}{{< yes >}}
Doppler API tokenDoppler API token{{< yes >}}{{< no >}}{{< yes >}}
Doppler Service tokenDoppler Service token{{< yes >}}{{< no >}}{{< yes >}}
Dropbox API secret/keyDropbox API secret/key{{< yes >}}{{< no >}}{{< no >}}
Dropbox App Access TokenDropboxAppAccessToken{{< yes >}}{{< no >}}{{< yes >}}
Dropbox long lived API tokenDropbox long lived API token{{< yes >}}{{< no >}}{{< no >}}
Dropbox short lived API tokenDropbox short lived API token{{< yes >}}{{< no >}}{{< yes >}}
Duffel API tokenDuffel API token{{< yes >}}{{< no >}}{{< no >}}
Dynatrace Platform TokenDynatracePlatformToken{{< yes >}}{{< no >}}{{< no >}}
EasyPost production API keyEasyPost API token{{< yes >}}{{< no >}}{{< no >}}
EasyPost test API keyEasyPost test API token{{< yes >}}{{< no >}}{{< no >}}
Facebook tokenFacebook token{{< yes >}}{{< no >}}{{< no >}}
Fastly API user or automation tokenFastly API token{{< yes >}}{{< no >}}{{< no >}}
Figma Personal Access TokenFigmaPersonalAccessToken{{< yes >}}{{< no >}}{{< yes >}}
Finicity API tokenFinicity API token{{< yes >}}{{< no >}}{{< no >}}
Finicity client secretFinicity client secret{{< yes >}}{{< no >}}{{< no >}}
Flutterwave Prod Encrypted KeyFlutterwaveProdEncryptedKey{{< yes >}}{{< no >}}{{< yes >}}
Flutterwave test encrypted keyFlutterwave encrypted key{{< yes >}}{{< no >}}{{< no >}}
Flutterwave Prod Public KeyFlutterwaveProdPublicKey{{< yes >}}{{< no >}}{{< yes >}}
Flutterwave test public keyFlutterwave public key{{< yes >}}{{< no >}}{{< no >}}
Flutterwave Prod Secret KeyFlutterwaveProdSecretKey{{< yes >}}{{< no >}}{{< yes >}}
Flutterwave test secret keyFlutterwave secret key{{< yes >}}{{< no >}}{{< no >}}
Frame.io API tokenFrame.io API token{{< yes >}}{{< no >}}{{< no >}}
GCP API keyGCP API key{{< yes >}}{{< no >}}{{< no >}}
GCP OAuth client secretGCP OAuth client secret{{< yes >}}{{< no >}}{{< yes >}}
GCP Vertex Express Mode KeyGCPVertexExpressModeKey{{< yes >}}{{< no >}}{{< yes >}}
GitHub app tokenGithub App Token{{< yes >}}{{< no >}}{{< yes >}}
GitHub App Installation TokenGithubAppInstallationToken{{< yes >}}{{< no >}}{{< yes >}}
GitHub Fine Grained Personal Access TokenGithubFineGrainedPersonalAccessToken{{< yes >}}{{< no >}}{{< yes >}}
GitHub OAuth Access TokenGithub OAuth Access Token{{< yes >}}{{< no >}}{{< yes >}}
GitHub personal access token (classic)Github Personal Access Token{{< yes >}}{{< no >}}{{< yes >}}
GitHub refresh tokenGithub Refresh Token{{< yes >}}{{< no >}}{{< yes >}}
GitLab CI/CD job tokengitlab_ci_build_token{{< yes >}}{{< yes >}}{{< no >}}
GitLab deploy tokengitlab_deploy_token{{< yes >}}{{< yes >}}{{< no >}}
GitLab Feature Flags Client TokenNone{{< no >}}{{< yes >}}{{< no >}}
GitLab feed tokengitlab_feed_token{{< yes >}}{{< yes >}}{{< no >}}
GitLab feed token v2gitlab_feed_token_v2{{< yes >}}{{< yes >}}{{< yes >}}
GitLab incoming email tokengitlab_incoming_email_token{{< yes >}}{{< yes >}}{{< yes >}}
GitLab Kubernetes agent tokengitlab_kubernetes_agent_token{{< yes >}}{{< yes >}}{{< yes >}}
GitLab OAuth application secretgitlab_oauth_app_secret{{< yes >}}{{< yes >}}{{< yes >}}
GitLab personal access tokengitlab_personal_access_token{{< yes >}}{{< yes >}}{{< yes >}}
GitLab Personal Access Token (routable)gitlab_personal_access_token_routable{{< yes >}}{{< yes >}}{{< yes >}}
GitLab pipeline trigger tokengitlab_pipeline_trigger_token{{< yes >}}{{< yes >}}{{< yes >}}
GitLab runner authentication tokengitlab_runner_auth_token{{< yes >}}{{< yes >}}{{< yes >}}
GitLab runner registration tokengitlab_runner_registration_token{{< yes >}}{{< no >}}{{< yes >}}
GitLab SCIM OAuth tokengitlab_scim_oauth_token{{< yes >}}{{< yes >}}{{< no >}}
GoCardless API tokenGoCardless API token{{< yes >}}{{< no >}}{{< no >}}
Google API keyGCP API key{{< yes >}}{{< no >}}{{< no >}}
Google (GCP) service accountGoogle (GCP) Service-account{{< yes >}}{{< no >}}{{< yes >}}
Grafana Service Account TokenGrafanaServiceAccountToken{{< yes >}}{{< no >}}{{< yes >}}
Grafana Cloud Access Policy TokenGrafanaCloudAccessPolicyToken{{< yes >}}{{< no >}}{{< yes >}}
HashiCorp Terraform API tokenHashicorp Terraform user/org API token{{< yes >}}{{< no >}}{{< yes >}}
HashiCorp Vault batch tokenHashicorp Vault batch token{{< yes >}}{{< no >}}{{< yes >}}
HashiCorp Vault Service TokenHashicorpVaultServiceToken{{< yes >}}{{< no >}}{{< yes >}}
Heroku API key or application authorization tokenHeroku API Key{{< yes >}}{{< no >}}{{< yes >}}
Highnote Live Secret KeyHighnoteLiveSecretKey{{< yes >}}{{< no >}}{{< yes >}}
Highnote Test Secret KeyHighnoteTestSecretKey{{< yes >}}{{< no >}}{{< yes >}}
HubSpot private app API tokenHubspot API token{{< yes >}}{{< no >}}{{< yes >}}
Hugging Face User Access TokenHuggingFaceUserAccessToken{{< yes >}}{{< no >}}{{< yes >}}
Instagram access tokenInstagram access token{{< yes >}}{{< no >}}{{< no >}}
Intercom API tokenIntercom API token{{< yes >}}{{< no >}}{{< no >}}
Intercom App Access TokenIntercomAppAccessToken{{< yes >}}{{< no >}}{{< yes >}}
Intercom client secret or client IDIntercom client secret/ID{{< yes >}}{{< no >}}{{< no >}}
Ionic personal access tokenIonic API token{{< yes >}}{{< no >}}{{< no >}}
JFrog Platform Access TokensJfrogPlatformAccessToken{{< yes >}}{{< no >}}{{< no >}}
Kubernetes Service Account TokenKubernetesServiceAccToken{{< yes >}}{{< no >}}{{< yes >}}
LangChain API KeyLangChainAPIKey{{< yes >}}{{< no >}}{{< yes >}}
Linear API tokenLinear API token{{< yes >}}{{< no >}}{{< yes >}}
Linear client secret or ID (OAuth 2.0)Linear client secret/ID{{< yes >}}{{< no >}}{{< no >}}
LinkedIn client IDLinkedin Client ID{{< yes >}}{{< no >}}{{< no >}}
LinkedIn client secretLinkedin Client secret{{< yes >}}{{< no >}}{{< no >}}
Lob API keyLob API Key{{< yes >}}{{< no >}}{{< no >}}
Lob publishable API keyLob Publishable API Key{{< yes >}}{{< no >}}{{< no >}}
Mailchimp API keyMailchimp API key{{< yes >}}{{< no >}}{{< yes >}}
Mailgun private API tokenMailgun private API token{{< yes >}}{{< no >}}{{< yes >}}
Mailgun public verification keyMailgun public validation key{{< yes >}}{{< no >}}{{< no >}}
Mailgun webhook signing keyMailgun webhook signing key{{< yes >}}{{< no >}}{{< yes >}}
Mapbox API tokenMapbox API token{{< yes >}}{{< no >}}{{< no >}}
Mapbox Secret API TokenMapboxSecretApiToken{{< yes >}}{{< no >}}{{< no >}}
MaxMind License KeyMaxMind License Key{{< yes >}}{{< no >}}{{< yes >}}
MessageBird access keymessagebird-api-token{{< yes >}}{{< no >}}{{< no >}}
MessageBird API client IDMessageBird API client ID{{< yes >}}{{< no >}}{{< no >}}
Meta access tokenMeta access token{{< yes >}}{{< no >}}{{< no >}}
New Relic ingest browser API tokenNew Relic ingest browser API token{{< yes >}}{{< no >}}{{< no >}}
New Relic ingest browser API token v2New Relic ingest browser API token v2{{< yes >}}{{< no >}}{{< yes >}}
New Relic REST API KeyNew Relic REST API Key{{< yes >}}{{< no >}}{{< yes >}}
New Relic user API IDNew Relic user API ID{{< yes >}}{{< no >}}{{< yes >}}
New Relic user API keyNew Relic user API Key{{< yes >}}{{< no >}}{{< yes >}}
npm access tokennpm access token{{< yes >}}{{< no >}}{{< yes >}}
Oculus access tokenOculus access token{{< yes >}}{{< no >}}{{< no >}}
Okta API TokenOktaAPIToken{{< yes >}}{{< no >}}{{< yes >}}
Okta Client SecretOktaClientSecret{{< yes >}}{{< no >}}{{< no >}}
Onfido Live API TokenOnfido Live API Token{{< yes >}}{{< no >}}{{< yes >}}
OpenAI API keyopen ai token{{< yes >}}{{< no >}}{{< no >}}
OpenAI Project KeyOpenAiProjectKey{{< yes >}}{{< no >}}{{< yes >}}
OpenAI Service Account KeyOpenAiServiceAccountKey{{< yes >}}{{< no >}}{{< yes >}}
Password in URLPassword in URL{{< yes >}}{{< no >}}{{< no >}}
PGP private keyPGP private key{{< yes >}}{{< no >}}{{< no >}}
PKCS8 private keyPKCS8 private key{{< yes >}}{{< no >}}{{< no >}}
PlanetScale API tokenPlanetscale API token{{< yes >}}{{< no >}}{{< yes >}}
PlanetScale App SecretPlanetscaleAppSecret{{< yes >}}{{< no >}}{{< yes >}}
PlanetScale OAuth SecretPlanetscaleOAuthSecret{{< yes >}}{{< no >}}{{< yes >}}
PlanetScale passwordPlanetscale password{{< yes >}}{{< no >}}{{< yes >}}
PostHog Personal API keyPostHogPersonalAPIkey{{< yes >}}{{< no >}}{{< yes >}}
PostHog Project API keyPostHogProjectAPIkey{{< yes >}}{{< no >}}{{< yes >}}
Postman API tokenPostman API token{{< yes >}}{{< no >}}{{< no >}}
Postman Collection Access KeyPostmanCollectionAccessKey{{< yes >}}{{< no >}}{{< yes >}}
Pulumi API tokenPulumi API token{{< yes >}}{{< no >}}{{< no >}}
PyPi upload tokenPyPI upload token{{< yes >}}{{< no >}}{{< yes >}}
RSA private keyRSA private key{{< yes >}}{{< no >}}{{< no >}}
RubyGems API tokenRubygem API token{{< yes >}}{{< no >}}{{< yes >}}
Segment public API tokenSegment Public API token{{< yes >}}{{< no >}}{{< yes >}}
SendGrid API tokenSendgrid API token{{< yes >}}{{< no >}}{{< yes >}}
Shippo API tokenShippo API token{{< yes >}}{{< no >}}{{< yes >}}
Shippo Test API tokenShippo Test API token{{< yes >}}{{< no >}}{{< no >}}
Shopify Partner API TokenShopifyPartnerAPIToken{{< yes >}}{{< no >}}{{< yes >}}
Shopify personal access tokenShopify access token{{< yes >}}{{< no >}}{{< yes >}}
Shopify private app access tokenShopify private app access token{{< yes >}}{{< no >}}{{< yes >}}
Shopify Custom App Access TokenShopify custom app access token{{< yes >}}{{< no >}}{{< yes >}}
Shopify shared secretShopify shared secret{{< yes >}}{{< no >}}{{< yes >}}
Slack App Configuration TokenSlackAppConfigurationToken{{< yes >}}{{< no >}}{{< yes >}}
Slack App Configuration Refresh TokenSlackAppConfigurationRefreshToken{{< yes >}}{{< no >}}{{< yes >}}
Slack app level tokenSlackAppLevelToken{{< yes >}}{{< no >}}{{< yes >}}
Slack bot user OAuth tokenSlack token{{< yes >}}{{< no >}}{{< yes >}}
Slack webhookSlack Webhook{{< yes >}}{{< no >}}{{< no >}}
SonarQube Global Analysis TokenSonarQubeGlobalAnalysisToken{{< yes >}}{{< no >}}{{< yes >}}
SonarQube Project Analysis TokenSonarQubeProjectAnalysisToken{{< yes >}}{{< no >}}{{< yes >}}
SonarQube User TokenSonarQubeUserToken{{< yes >}}{{< no >}}{{< yes >}}
Splunk Authentication TokenSplunkAuthToken{{< yes >}}{{< no >}}{{< yes >}}
Splunk HTTP Event Collector (HEC) TokenSplunkHECToken{{< yes >}}{{< no >}}{{< no >}}
SSH (DSA) private keySSH (DSA) private key{{< yes >}}{{< no >}}{{< no >}}
SSH (EC) private keySSH (EC) private key{{< yes >}}{{< no >}}{{< no >}}
SSH private keySSH private key{{< yes >}}{{< no >}}{{< no >}}
Stripe live restricted keyStripeLiveRestrictedKey{{< yes >}}{{< no >}}{{< yes >}}
Stripe live secret keyStripeLiveSecretKey{{< yes >}}{{< no >}}{{< yes >}}
Stripe Live Short Secret KeyStripeLiveShortSecretKey{{< yes >}}{{< no >}}{{< yes >}}
Stripe publishable live keyStripeLivePublishableKey{{< yes >}}{{< no >}}{{< no >}}
Stripe publishable test keyStripeTestPublishableKey{{< yes >}}{{< no >}}{{< no >}}
Stripe restricted test keyStripeTestRestrictedKey{{< yes >}}{{< no >}}{{< no >}}
Stripe secret test keyStripeTestSecretKey{{< yes >}}{{< no >}}{{< no >}}
Stripe Test Short Secret KeyStripeTestShortSecretKey{{< yes >}}{{< no >}}{{< yes >}}
Tailscale OAuth Client SecretTailscaleOauthClientSecret{{< yes >}}{{< no >}}{{< yes >}}
Tailscale API Access TokenTailscaleApiAccessToken{{< yes >}}{{< no >}}{{< yes >}}
Tailscale Personal Auth KeyTailscalePersonalAuthKey{{< yes >}}{{< no >}}{{< yes >}}
Tencent Cloud Secret IDTencentCloudSecretID{{< yes >}}{{< no >}}{{< yes >}}
Twilio Account SIDTwilio Account SID{{< yes >}}{{< no >}}{{< yes >}}
Twilio API keyTwilio API Key{{< yes >}}{{< no >}}{{< yes >}}
Twitch OAuth client secretTwitch API token{{< yes >}}{{< no >}}{{< no >}}
Typeform personal access tokenTypeform API token{{< yes >}}{{< no >}}{{< no >}}
Volcengine Access Key IDVolcengineAccessKeyID{{< yes >}}{{< no >}}{{< yes >}}
WakaTime API KeyWakaTimeAPIKey{{< yes >}}{{< no >}}{{< yes >}}
X tokenTwitter token{{< yes >}}{{< no >}}{{< no >}}
Yandex.Cloud AWS API compatible access secretYandex.Cloud AWS API compatible Access Secret{{< yes >}}{{< no >}}{{< no >}}
Yandex.Cloud API KeyYandex.Cloud API Key{{< yes >}}{{< no >}}{{< no >}}
Yandex.Cloud IAM cookie v1-1Yandex.Cloud IAM Cookie v1 - 1{{< yes >}}{{< no >}}{{< no >}}
Yandex.Cloud IAM cookie v1-3Yandex.Cloud IAM Cookie v1 - 3{{< yes >}}{{< no >}}{{< no >}}
<!-- vale gitlab_base.SentenceSpacing = YES --> <!-- vale gitlab_base.Spelling = YES --> <!-- markdownlint-enable MD044 -->